Sernixa logoSernixa

Privacy

Privacy Policy

This policy explains what Sernixa collects, why it is used, when it is shared, how long it is kept, and the choices available to individuals.

Effective date: July 17, 2026

Last updated: July 17, 2026

1. Scope

This Privacy Policy applies when you visit Sernixa websites, create or use a hosted account or workspace, use Sernixa APIs, SDKs, command-line tools or local agents, connect an integration, communicate with us, or receive support. It covers personal information processed by Sernixa, Inc. ("Sernixa," "we," "us," or "our").

This policy does not govern a third-party service you connect to Sernixa or a customer-controlled deployment that does not send data to Sernixa. Those services and deployments have their own privacy terms.

2. When Sernixa Is a Controller or Processor

Sernixa acts as a controller (also called a business or data fiduciary in some laws) for website, account, billing, support, security, and service-analytics data when we determine why and how it is processed.

For personal data submitted by a customer through governance actions, evidence, audit records, integrations, or connected runtimes, Sernixa generally acts as the customer’s processor or service provider. The customer determines the purpose and instructions, handles notices and permissions for its data subjects, and is the first contact for requests about that Customer Data. A data processing agreement or Order Form may provide additional terms.

3. Information We Collect

  • -Account and identity data: name, business email address, profile image, Google or other configured identity-provider identifiers and claims, sign-in status, and session identifiers.
  • -Organization and access data: organization and team names, role, permissions, invitations, membership, administrator actions, plan, region, and workspace settings.
  • -Governance and Customer Data: action metadata and content, prompts or model output a customer chooses to submit, policy inputs and results, risk levels, approvals and reviewer comments, delegation chains, audit events, evidence payloads, DLP findings, circuit-breaker events, and export records.
  • -Agent, MCP, and discovery data: agent and machine identifiers, labels, versions, runtime and service metadata, tool or server names, endpoints, configuration observations, discovery candidates, enrollment state, sync status, and limited process, file, network, or eBPF observations enabled by the customer.
  • -Integration and credential metadata: connected provider, workspace or channel identifiers, scopes, status, webhook or callback configuration, API-key identifier and prefix, signature or verification status, and token lifecycle events. Raw secrets are processed only as needed to establish or operate the connection.
  • -Billing and transaction data: plan, price, currency, billing interval, region, subscription status, provider customer and subscription identifiers, invoice or payment status, and tax or business details. When hosted checkout is used, the payment processor—not Sernixa—receives full card or bank credentials.
  • -Technical, usage, and security data: IP address, request date and time, requested URL, referrer, browser, operating system, device type, approximate country or region, SDK or agent version, service identity, diagnostics, error and availability events, request metadata, nonce or replay status, and security reason codes.
  • -Communications: questions, feedback, support requests, call or meeting details, and other information you choose to send us.

Please do not submit personal data that is unnecessary for the governance purpose, or passwords, raw private keys, full payment-card data, government identifiers, health data, biometric identifiers, children’s data, or other highly sensitive data unless an applicable written agreement expressly supports that processing.

4. Sources of Information

  • -Directly from you when you sign in, configure a workspace, choose a plan, contact us, or operate an SDK, API, or local agent.
  • -From your organization, such as an administrator, inviter, reviewer, or connected runtime.
  • -From identity, payment, collaboration, cloud, registry, and other providers you or your organization connect.
  • -Automatically from browsers, devices, servers, SDKs, APIs, logs, and security controls when the Services are used.
  • -From public sources when a feature imports public MCP registry, package, repository, or service metadata. Public-source provenance is retained where the feature supports it.

6. AI, Model Output, and Governance Data

Sernixa may process raw or normalized model and tool output when a customer submits it for policy evaluation, Counterfactual Twin, Intervention Trace, approval review, evidence, or another enabled feature. The customer controls what is submitted and who may review it.

Sernixa does not use Customer content to train a general-purpose AI model unless that use is expressly disclosed and authorized in a separate written agreement. Customer-enabled third-party model providers may process data under the customer’s configuration and their own terms.

7. Cookies, Local Storage, and Analytics

Sernixa uses strictly necessary technologies to keep accounts secure and remember requested product state. Auth.js places a secure sign-in session cookie; the standard session maximum is 30 days and may refresh while the account remains active. The plan-selection flow may use browser local storage or a short-lived first-party cookie so the requested plan survives a redirect. Blocking necessary storage may prevent sign-in or other requested features.

Sernixa uses Vercel Web Analytics for page-view and aggregate website statistics. In the current configuration, it does not use analytics cookies. Vercel derives a daily visitor hash from request data, discards the visitor identifier after 24 hours, and reports aggregate information such as page, referrer, country, browser, operating system, and device type. We do not use this analytics data for cross-site behavioral advertising.

If we introduce non-essential cookies or advertising technology, we will update this policy and provide any choice or consent mechanism required by law before using it.

8. How We Disclose Information

We disclose only the information reasonably needed for the purpose. Depending on the deployment and features enabled, recipient categories may include:

  • -Infrastructure, hosting, database, cache, security, and observability providers, such as Vercel, Convex, AWS, Azure, Postgres, Redis, or comparable providers configured for the deployment.
  • -Identity providers, such as Google or a customer-configured enterprise identity provider.
  • -Payment processors, such as Stripe or Razorpay where the relevant regional billing path is enabled.
  • -Customer-authorized integrations, such as Slack, Microsoft Teams, model providers, registries, webhooks, or other systems selected by the customer.
  • -Professional advisers, auditors, insurers, and vendors bound to use the information only for the service they provide.
  • -Authorities or other parties when we reasonably believe disclosure is required by law, needed to protect rights or safety, or necessary to investigate fraud, abuse, or a security incident.
  • -A buyer, successor, or relevant adviser in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice where required.
  • -Other recipients at your direction or with your consent.

Organization administrators and authorized reviewers can access information within their organization according to roles and permissions. Sernixa does not control how a customer independently exports, shares, or uses Customer Data.

9. No Sale or Behavioral Advertising

Sernixa does not sell personal information for money and does not share personal information for cross-context behavioral advertising or targeted advertising as those terms are defined by applicable U.S. state privacy laws. We do not use sensitive personal information to infer characteristics about individuals. Because we do not conduct those activities, a sale or targeted-advertising opt-out is not currently necessary. If this changes, we will update this policy and honor applicable opt-out preference signals, including Global Privacy Control where required.

10. International Data Transfers

Sernixa and its providers may process information in countries other than the country where it was collected. Privacy protections may differ. Where required, we use a lawful transfer mechanism such as contractual protections, an adequacy decision, or another approved safeguard, and apply any applicable Indian transfer restriction or customer-agreed residency term. Contact us to request information about safeguards relevant to your data.

11. Data Retention

We keep personal information only for as long as reasonably necessary for the purpose described, the customer’s instructions and plan, security and audit integrity, dispute resolution, and legal obligations. The criteria below apply unless an Order Form, data processing agreement, legal hold, or law requires a different period:

  • -Account, organization, and settings data: while the account or workspace is active, followed by a limited deletion and backup-rotation period.
  • -Authentication sessions: up to 30 days in the standard hosted configuration, subject to earlier sign-out, revocation, or administrator action.
  • -Governance, approval, audit, discovery, and evidence data: for the retention period associated with the customer plan or Order Form and as needed to preserve requested audit integrity. A separate security or legal record may be retained longer.
  • -Integration configuration and credential metadata: while the integration is active and for the limited period needed to confirm disconnection, investigate abuse, or preserve an audit record. Disconnecting Sernixa does not automatically delete data held by the third-party provider.
  • -Billing and transaction records: for the subscription and the additional period required for tax, accounting, fraud prevention, and dispute obligations.
  • -Support communications: while the request is active and for a reasonable period afterward to document the resolution and improve support.
  • -Security and diagnostic logs: for the period needed to detect, investigate, remediate, and prevent incidents, including any minimum period required by applicable law.
  • -Vercel analytics: the daily visitor identifier is discarded after 24 hours; aggregate reporting availability depends on the Vercel plan and is generally 1 to 24 months.

Deletion may take additional time in encrypted backups, where data remains isolated until the backup is overwritten. We may retain de-identified information that is not reasonably capable of being linked to an individual. Customers control deletion of data that remains solely in their local or self-hosted environment.

12. Security and Incident Response

We use reasonable administrative, technical, and organizational measures designed to protect personal information. Depending on the feature and deployment, these include access controls, scoped roles and credentials, encryption in transit, protected secrets, signed request envelopes, replay controls, logging, and audit-integrity mechanisms.

No system is risk-free. Customers must secure their endpoints, accounts, networks, integrations, local agents, and exported data. If we confirm a personal-data breach, we will investigate, take reasonable mitigation steps, and notify affected customers, individuals, or authorities as required by applicable law and our contractual role.

13. Automated Decisions

Sernixa provides policy evaluation, risk classification, simulations, evidence, and approval routing. For Sernixa’s own purposes, we do not use personal information to make solely automated decisions that produce legal or similarly significant effects about an individual. Customers decide how to configure and use governance results and are responsible for required explanations, impact assessments, human review, and appeal rights for their own use cases.

14. Your Privacy Rights and Choices

Depending on where you live and subject to legal exceptions, you may ask to access, know about, correct, delete, or receive a portable copy of personal information; restrict or object to processing; withdraw consent; opt out of certain disclosures or automated decisions; appeal a denied request; nominate or authorize another person; and receive equal service without unlawful discrimination for exercising a right.

For account data controlled by Sernixa, send a request to contact@sernixa.com with the subject "Privacy Request." Include your account email, organization, country or state, the right requested, and enough detail to locate the data. Do not send identity documents unless we request a secure verification method. We may verify the request through the account, email, administrator, or other proportionate information and may need to confirm an authorized agent’s authority.

For Customer Data controlled by your employer or another Sernixa customer, contact that organization first. We will assist the customer as required by contract and law. You may withdraw consent using the same account or integration control used to grant it where available, or by contacting us. We will respond within the period required by applicable law and explain any denial and available appeal or complaint route.

15. Regional Notices

European Economic Area and United Kingdom. Section 5 identifies our legal bases. You may exercise the rights in section 14 and lodge a complaint with your local data-protection authority. Where legitimate interests apply, you may request information about the balancing considered. International transfers use the safeguards described in section 10.

India. Where the Digital Personal Data Protection Act and its rules apply, you may request access to processing information, correction, completion, updating or erasure, use the grievance process, withdraw consent, or nominate another person as provided by law. Send a grievance or rights request to contact@sernixa.com. We will publish or provide any additional mechanism required as relevant provisions take effect.

California and other U.S. states. In the preceding 12 months, Sernixa collected the categories in section 3 from the sources in section 4, used them for the purposes in section 5, and disclosed relevant categories for business purposes to the recipients in section 8. Sernixa did not sell or share them for cross-context behavioral advertising and has no actual knowledge that it sold or shared personal information of anyone under 16. Applicable residents may exercise the rights in section 14, including correction, deletion, access, portability, opt-out, or appeal rights available under their state law.

16. Children

The Services are intended for business users who are at least 18. Sernixa does not knowingly offer accounts to or collect personal information directly from children. Do not submit children’s personal information through the Services without a lawful basis, required parental authorization, and an applicable written agreement. If you believe a child’s information was submitted improperly, contact us so we can investigate and delete it where required.

17. Customer Privacy Responsibilities

  • -Tell Authorized Users and other affected individuals how Customer uses Sernixa and identify Customer as the controller or data fiduciary where applicable.
  • -Submit only data Customer is authorized to process and configure collection, approvals, integrations, access, and retention consistently with Customer’s notices and legal obligations.
  • -Respond to rights requests for Customer Data and notify Sernixa when assistance is needed.
  • -Avoid secrets and unnecessary sensitive data in prompts, policy context, evidence, logs, discovery labels, URLs, or support messages.
  • -Review third-party integration settings and disconnect or revoke access in both Sernixa and the third-party service when appropriate.

18. Changes to This Policy

We may update this policy as the Services, providers, or legal requirements change. We will post the revised policy with a new last-updated date. If a change materially affects how we use personal information, we will provide additional notice through the Service or by email where required and seek consent where applicable law requires it.

19. Contact and Grievances

Sernixa, Inc. is the contact for this policy. Send privacy questions, rights requests, or grievances to contact@sernixa.com with the subject "Privacy Request" or "Privacy Grievance." Account and security support may be sent to support@sernixa.com. Include your account email, organization, location, and a clear description, but do not email passwords, raw API keys, payment-card data, or unnecessary identity documents.